Last updated: 3 August 2026
Quick Answer: The EU AI Act is Regulation (EU) 2024/1689, the first comprehensive law on artificial intelligence. It sorts AI systems into four risk levels, prohibits a small set of practices outright, sets strict obligations for high-risk and general-purpose AI, and applies even to providers and deployers outside the EU whenever an AI system's output is used within the Union. It entered into force on 1 August 2024 and applies in stages up to 2 August 2027.
The EU artificial intelligence act is the first regulatory framework for artificial intelligence in the world that adopts a horizontal approach. This act was enacted as regulation (EU) 2024/1689 of June 13, 2024 and published in the Official Journal on July 12, 2024. In essence, this legal act takes the risk-based approach: the higher the risk of the AI system concerning health, safety, or fundamental rights, the stricter requirements apply to it. In this guide, the scope of this act, criteria for application, risk categories, duties of the suppliers and users of AI systems, rules on the use of general-purpose AI, possible sanctions, and timing of enforcement is explained.
| The EU AI Act at a glance | Detail |
|---|---|
| Instrument | Regulation (EU) 2024/1689 (the Artificial Intelligence Act) |
| Adopted | 13 June 2024; published in the Official Journal 12 July 2024 |
| Entry into force | 1 August 2024 |
| General application | 2 August 2026 (with staggered exceptions from 2 February 2025 to 2 August 2027) |
| Approach | Risk-based: unacceptable, high, limited and minimal risk |
| Territorial reach | Extraterritorial - binds non-EU providers and deployers where AI output is used in the Union |
| Maximum penalty | Up to €35 million or 7% of total worldwide annual turnover |
What is the EU AI Act?
The EU AI Act represents a key piece of European legislation giving rise to uniform procedures applicable to the processes of development, promotion, supply and use of various AI systems within the confines of the EU. Article 1 of the present legislation states that its main objective is aimed at ensuring that the AI technologies are trustworthy and oriented towards human beings while at the same time providing for the protection of health and safety and fundamental rights established by the Charter of Fundamental Rights such as democracy, rule of law and environmental protection.
How is the EU AI Act structured?
Rather than establishing general technology regulations, the Act controls the utilization of AI depending on the risk it involves, including banning a handful of practices, imposing terms of service on high-risk technologies, activating the mandate for disclosure for medium-risk technologies, and creating a dedicated law for the general-purpose AI model.
How does the EU AI Act define an AI system?
The AI system, as defined in Article 3(1), is an automated system with varying levels of independence and an ability to adapt once it is in operation. The AI system is able to draw conclusions from the information it receives and deliver its output in the form of predictions, results, recommendations or decisions in accordance with its expressed or hidden goals. The definition is deliberately ambiguous and neutral with respect to technology.
Who does the EU AI Act apply to?
Based on Article 2 of the Act, the coverage of the law is very wide as regards its users. In fact, the Act is applicable not only to the firms providing AI systems to Europe, but also to the businesses located in EU, which use AI in any circumstance, as well as the importers of AI systems, sellers, producers and agents of the organizations from outside of EU. The people who fall under the scope of the law and who are located in the EU will be protected as well.
Who is a provider and who is a deployer?
As per legal provisions, there exist primarily two kinds of participants in the process. First, there is the provider (Article 3(3)), which refers to the person who introduces a particular technology or model of AI to the market using their brand name. Then, there is the deployer (Article 3(4)), who is responsible for utilizing the AI model in one's professional activity. In summary, while the responsibility lies primarily with providers, the deployers of AI model have their own obligations.
Does the EU AI Act apply to companies outside the EU?
In fact, Article 2(1)(c) makes it essential for organizations and persons operating in third jurisdictions to comply with the Act regarding the outputs of their AI systems, provided the outputs are used within the EU. The provision illustrates the European Union's inclination towards the solution of the General Data Protection Regulation, which makes it unnecessary for a business to operate within Europe. This means that if an AI system of an Indian software business processes data that is utilized in Europe, the company will have to comply with the Act.
What is excluded from the EU AI Act?
Article 2 of the Act includes several exclusions. The Act will not cover such geographical areas that are outside the territorial scope of Union law or areas that can be determined by national security considerations. Additionally, all instances of AI development carried out specifically for military or national security purposes can be taken out of the scope of the Act too. The same applies to cases when an AI is being used for research and development of scientific purposes only. Also, those research and testing activities performed prior to the launch of the relevant AI system on the market can be excluded from the scope of the Act as well, except for those conducted in real time. The provisions of the Act do not apply to available for free and open-source AI products unless such products are on sale as high risk products or those violating the applicable rules regarding prohibited activities or transparency. Individuals' private non-professional use of AI is excluded from the scope of the Act as well.
How does the EU AI Act classify AI systems?
The Act sorts AI into four tiers by risk. The tier determines the obligations that apply.
| Risk tier | How the Act treats it | Typical examples |
|---|---|---|
| Unacceptable risk | Prohibited outright (Article 5) | Social scoring, manipulative or exploitative AI, untargeted facial-image scraping |
| High risk | Strict requirements plus conformity assessment (Articles 8-15) | Recruitment and CV-screening tools, credit scoring, biometric identification, AI safety components in regulated products |
| Limited risk | Transparency obligations (Article 50) | Chatbots, deepfakes and other synthetic content |
| Minimal risk | No specific obligations under the Act | Spam filters, AI in video games, inventory optimisation |
What AI practices does the EU AI Act prohibit?
Article 5 outlaws specific behaviors imputed to have unreasonable risks. Article 5 came into operation on February 2, 2025, which is prior to the commencement of the rest of the regulation.
- Subliminal, manipulative or deceptive techniques that materially distort behaviour and are likely to cause significant harm.
- Exploitation of vulnerabilities arising from age, disability or a specific social or economic situation.
- Social scoring - evaluating or classifying people over time by social behaviour or personal characteristics, leading to detrimental treatment in unrelated contexts or that is unjustified or disproportionate.
- Individual predictive policing based solely on profiling or personality traits.
- Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.
- Emotion recognition in the workplace and in education institutions, except for medical or safety reasons.
- Biometric categorisation that infers race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation.
- Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrow exceptions such as searching for victims of trafficking or preventing an imminent terrorist threat, and only with prior judicial or administrative authorisation.
What is a high-risk AI system under the EU AI Act?
The Act is focused on high-risk arrangements. The Act's central rule follows two routes. Firstly, if an AI solution is an essential element of a product or if it is a product subject to European harmonization legislation laid down in Annex I, it will be classified as high-risk. Secondly, an AI solution will also be considered high-risk if it is used in any area listed in Annex III.
- Biometrics, including remote biometric identification, biometric categorisation and emotion recognition.
- Critical infrastructure, such as safety components in road traffic or the supply of water, gas, heating and electricity.
- Education and vocational training, including admission, evaluation of learning outcomes and monitoring during tests.
- Employment and worker management, including recruitment, filtering of applications, and decisions on promotion, termination and task allocation.
- Essential private and public services, including eligibility for public benefits, creditworthiness and credit scoring, risk assessment and pricing for life and health insurance, and emergency-call triage.
- Law enforcement, including risk assessments and evidence-reliability evaluation.
- Migration, asylum and border control, including risk assessment and examination of applications.
- Administration of justice and democratic processes, including assisting a judicial authority and influencing elections.
When is an Annex III system not high-risk?
Article 6(3) has a minor exemption that helps to prevent an Annex III system from being considered high risk as long as the system takes on a limited procedural or preparatory role with no important effect on the decision outcome. Nevertheless, any profiling of individuals counts as high risk. The provider should provide a self-assessment that indicates low risk in addition to filing the system.
What must providers of high-risk AI systems do?
The Act consists of Articles 8 to 15, which determine how a high-risk system complies with the relevant requirements prior to entering the market.
| Requirement | Article | What it demands |
|---|---|---|
| Risk management system | Article 9 | A continuous, iterative process across the whole lifecycle to identify, evaluate and mitigate risks, with special care for persons under 18 |
| Data and data governance | Article 10 | Training, validation and testing datasets that are relevant, representative and, as far as possible, free of errors, with bias examination and mitigation |
| Technical documentation | Article 11 | Documentation drawn up before market entry, meeting the minimum in Annex IV, with a simplified form for SMEs |
| Record-keeping (logging) | Article 12 | Automatic logging of events across the system's lifetime to ensure traceability |
| Transparency to deployers | Article 13 | Clear instructions for use covering capabilities, limitations, accuracy and human-oversight measures |
| Human oversight | Article 14 | Design that lets a person understand, override or stop the system; biometric identification needs verification by at least two people |
| Accuracy, robustness and cybersecurity | Article 15 | Declared accuracy levels and resilience against errors and against data poisoning, model poisoning and adversarial attacks |
What other duties do high-risk providers have?
Moreover, suppliers must have a quality management system, retain documentation for a period of 10 years, undergo a conformity assessment, prepare an EU declaration of conformity, comply with CE marking requirements for the product, and register in the EU database, according to Article 16. A supplier located outside of Europe must appoint an authorized representative in the EU in accordance with Article 22.
What are the obligations for deployers?
Those who implement systems ought to take an active approach. As per Article 26, they need to make sure they deploy a high-risk system and give appropriate guidance and instructions to well-trained individuals. These individuals should be responsible for verifying the authenticity of information used, monitoring the system closely, and submitting reports of any serious incident in a timely manner. If any of the workers are affected by the deployment of the system, they need to receive prior information from the person responsible for deployment.
What is a fundamental-rights impact assessment?
As indicated in Article 27, a fundamental rights impact assessment is required for certain entities referred to as deployers, such as both public institutions and private businesses that provide public services and use credit rating or life and health insurance systems. The assessment should describe how deployment will take place and who may be affected, identify the risks involved in its deployment, and what human oversight and management measures will be taken, and may involve conducting a data protection impact assessment pursuant to GDPR.
How does the EU AI Act regulate general-purpose AI?
The regulation provides an independent framework for general-purpose AI models developed for carrying out diverse activities. As per Article 53, any organization using general-purpose AI models has to keep the technical documentation, share information on the model with its users, design the copyright policy based on EU regulations, and release a summary of information used for training purposes. Organizations that implement open-source models do not have to keep technical documentation, they still, however, must comply with the requirement to make the copyright policy and to publish the summary.
What are the rules for GPAI with systemic risk?
GPAI models relating to systemic risk face stricter requirements. In this regard, Article 51 states that the model should have the ability to perform high-risk activities that can cause systemic risk only if the training of such a model requires more than 10^25 FLOPS of computing power. The model provider is obliged to inform the Commission as soon as such a requirement is fulfilled and in any case within two weeks. Article 55 obliges these providers to carry out model evaluation and adversarial testing, control, mitigate systemic risks, and monitor and report serious events.
What transparency rules apply to AI-generated content?
As per Article 50, the systems which are classified as middle level systems should fulfill transparency obligation. One of such obligations comprises developing the systems that may interact with human beings (for instance chatbots) in such a way that users realize that they are communicating with AI. Moreover, any AI-generated video, image, audio, or text content should bear a mark indicating that it is machine-made. Anyone who creates deepfake content must ensure that this content is recognized as artificial, which is also true for others, including those using the systems of emotion recognition or biometric classification.
Who enforces the EU AI Act?
Collaboration is the key to enforcement. In fact, the European Commission has an AI Office that tracks the development of AI technologies across Europe. All EU member states have established the European Artificial Intelligence Board, which collaborates and coordinates action in the field of AI before its application. An advisory board and scientific committee provide assistance in the matter of giving recommendations regarding potential threats and risks. In turn, each EU member country must establish an authority for notifications and an authority for market control, within the European Commission's wider regulatory framework for AI.
What are the penalties under the EU AI Act?
According to Article 99 of the Treaty on the Functioning of the EU, EU countries must implement measures to create sanctions that are effective and proportionate so that the sanctions can be applied in the best manner based on the gravity of the offense.
| Type of breach | Maximum fine |
|---|---|
| Breach of the prohibited practices in Article 5 | €35 million or 7% of total worldwide annual turnover, whichever is higher |
| Breach of other obligations by providers, deployers, importers, distributors or notified bodies, including transparency | €15 million or 3% of total worldwide annual turnover |
| Supplying incorrect, incomplete or misleading information to authorities | €7.5 million or 1% of total worldwide annual turnover |
How do penalties apply to smaller companies?
With regard to small and medium enterprises and their new inventions, the requirement found in Article 99(6) makes an exemption from the general rules since the principle of applying fixed figures has been modified whereby the entity with the minimum amount of money applies either of the two formulas.
When does the EU AI Act take effect?
The Act entered into force on 1 August 2024 but applies in stages, giving organisations time to prepare.
| Date | What becomes applicable |
|---|---|
| 1 August 2024 | Regulation enters into force |
| 2 February 2025 | Prohibited practices (Article 5) and AI-literacy duties (Article 4) |
| 2 August 2025 | General-purpose AI rules, governance provisions, penalties and notified-body rules |
| 2 August 2026 | General application, including most high-risk (Annex III) and transparency obligations |
| 2 August 2027 | High-risk obligations for AI in products covered by the Annex I product-safety route |
What does the EU AI Act mean for Indian companies?
Because the Act refers to non-EU players whose AI output is deployed within the EU, technology, analytics, human resource, and business processing firms from India may become either providers or deployers when serving EU clients. For instance, an Indian business that supplies a CV screening algorithm or credit scoring technology to a customer in an EU member state may be running a high-risk AI that entails obligations for proper governance, proper risk management, and the maintenance of technical documentation.
How should an Indian company respond?
A company from India must identify which artificial intelligence technologies are in application in European nations and be categorizing their levels of risk. Findings must be recorded in a system rather than merely in a spreadsheet. Companies that have already initiated the tracking of local compliance on a compliance management platform are able to use similar techniques while complying with international laws such as the EU AI Act, and can seek professional advisory support where a classification is uncertain. All sources including legal texts and regulatory sources and the EUR-Lex database must be monitored for updates.
Legal Disclaimer
This article is general information about the EU Artificial Intelligence Act and does not constitute legal advice. Organisations should verify their specific obligations against the current text of Regulation (EU) 2024/1689 and, where necessary, seek qualified professional advice.
Frequently Asked Questions
What is the EU AI Act in simple terms?
The EU AI Act, Regulation (EU) 2024/1689, is the first comprehensive law on artificial intelligence. It classifies AI systems by risk, bans a few practices outright, imposes strict requirements on high-risk and general-purpose AI, and sets transparency duties for systems such as chatbots and deepfakes.
When does the EU AI Act come into force?
The Act entered into force on 1 August 2024 and applies in stages. Prohibited practices applied from 2 February 2025, general-purpose AI and governance rules from 2 August 2025, general application from 2 August 2026, and the product-safety high-risk route from 2 August 2027.
Does the EU AI Act apply to companies outside the EU?
Yes. Under Article 2, the Act applies to providers and deployers located outside the EU whenever the output of their AI system is used in the Union. A company does not need an establishment in Europe to fall within scope, so Indian firms serving EU clients can be covered.
What are the penalties under the EU AI Act?
Fines scale with the breach. Using a prohibited practice can cost up to €35 million or 7% of worldwide annual turnover; breaching other obligations up to €15 million or 3%; and giving authorities incorrect information up to €7.5 million or 1%. Lower ceilings apply to small and medium-sized enterprises.
What is a high-risk AI system under the EU AI Act?
A high-risk system is one used in a sensitive area listed in Annex III, such as recruitment, credit scoring, biometric identification, education or essential services, or an AI safety component in a regulated product. High-risk systems must meet strict requirements on risk management, data governance, human oversight and cybersecurity.
What is a general-purpose AI model under the EU AI Act?
A general-purpose AI model is a model that shows significant generality and can perform a wide range of tasks, such as a large foundation model. Its provider must keep documentation, respect copyright law and publish a training-data summary; models trained above 10^25 floating-point operations face extra systemic-risk duties.